PCI-2.3:

From HORSE - Holistic Operational Readiness Security Evaluation.
Revision as of 13:58, 28 February 2007 by Mdpeters (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search


From the sample of (insert number and or description of sample) system components, verify that non-console administrative access is encrypted by:


PCI-2.3 A: Observing an administrator log on to each sampled system to determine that SSH (or other encryption method) is invoked before the administrator’s password is requested.


PCI-2.3 B: Reviewing services and parameter files on sampled systems to determine that Telnet and other remote log-in commands are not available for use internally.


PCI-2.3 C: Verifying that administrator access to the wireless management interface is encrypted with SSL/TLS. Alternatively, verify that administrators cannot connect remotely to the wireless management interface (all management of wireless environments is only from the console).



Testing Procedures

Insert testing guidance here.

Testing Frequency

Describe testing frequency here.

Evidence Archive Location

Insert hyperlink or location of evidence archive.

Control Stewards Process Narrative

Provide control steward commentary indicating the formal methodology in place.


Control Steward – Jon Doe

Process Illustration

Replace this test by inserting a process diagram, flowchart or other visual representation to illustrate the process narrative as necessary. Include a brief description of the process illustration.

Control Status and Auditors Commentary

The control is effective.


File:Greenlock.jpg

Status is acceptable.

Control Exception Commentary

Status is acceptable.

Remediation Plan

Remediation is not required at this time.


--Mdpeters 08:57, 28 February 2007 (EST)